| Posted | Nick | Remark | |
|---|---|---|---|
| #openstack-nova - 2023-01-13 | |||
| 14:33:22 | sean-k-mooney | well i have swaped back to other thing but in generally all active contibutor are exepcted to help look at them | |
| 14:33:30 | dansmith | sean-k-mooney: I saw one of those connection refused to rabbit things yesterday as well | |
| 14:33:45 | sean-k-mooney | bauzas: i would agree but as i said this is the second tim i have seen the rabbit issues | |
| 14:33:46 | dansmith | along with several other failures that has me concerned | |
| 14:33:53 | sean-k-mooney | ya | |
| 14:33:55 | bauzas | lemme check the nodes | |
| 14:34:14 | sean-k-mooney | so i do think that something has regressed in grenade/devstack/job-defintiosn | |
| 14:34:52 | sean-k-mooney | it could be provider related but i think we have seen isseus on more the one provider | |
| 14:35:02 | dansmith | on another note, sean-k-mooney bauzas I hope either of you can look at this soon: https://review.opendev.org/c/openstack/nova/+/866218 | |
| 14:35:12 | bauzas | https://f4c3b65ecec7dfeb9b12-92114ee8da6f13c40794db32b7bbd824.ssl.cf5.rackcdn.com/869950/4/check/nova-grenade-multinode/9c1b4d7/zuul-info/inventory.yaml | |
| 14:35:16 | bauzas | ovh | |
| 14:35:22 | dansmith | still waiting on one devstack thing, but it's small, and a dependent placement thing as well | |
| 14:35:32 | bauzas | dansmith: sure I can help | |
| 14:35:43 | bauzas | oh this | |
| 14:35:52 | bauzas | I said I was looking at it | |
| 14:35:54 | sean-k-mooney | dansmith: ya so i merged the placment fixture change last night | |
| 14:36:04 | dansmith | oh sweet thanks | |
| 14:36:22 | bauzas | already half-reviewed gmann's patch | |
| 14:36:23 | sean-k-mooney | bauzas: ack if you dont get to it by your end of day ill try and get to it before i sign off today | |
| 14:36:29 | kashyap | sean-k-mooney: Yes, of course - I look at them (within reason). I was just saying, can't drop all the other responsibilities and tend to it :( Just not enough hours | |
| 14:36:30 | dansmith | bauzas: sorry, but thanks | |
| 14:36:47 | dansmith | kashyap: well, someone has to :/ | |
| 14:37:08 | kashyap | dansmith: True, the mythical "someone"; it's the classic "tragedy of the commons" :/ | |
| 14:37:09 | dansmith | if we let it get out of control we'll never recover | |
| 14:37:35 | bauzas | sean-k-mooney: gmann: ok, so by now we only check functional tests using legacy RBAC | |
| 14:37:37 | bauzas | https://review.opendev.org/c/openstack/placement/+/869525/3/placement/tests/functional/fixtures/placement.py | |
| 14:37:43 | bauzas | I'm OK with this | |
| 14:38:08 | bauzas | but will we have a FUP modifying our tests for using the new defaults ? | |
| 14:38:37 | dansmith | bauzas: no, the main devstack job runs with old | |
| 14:38:42 | dansmith | and a new devstack job with new | |
| 14:39:03 | dansmith | that's what I had him add, so we could command them still to be old while we transition | |
| 14:40:38 | sean-k-mooney | well bauzas is askign about functional tests | |
| 14:40:44 | bauzas | dansmith: ok, I understand it so placement won't yet support new defaults, only nova/neutron/cinder blah, right? | |
| 14:40:59 | sean-k-mooney | at some point we shoudl test with new placemnt defaults too | |
| 14:41:05 | bauzas | that's my point | |
| 14:41:16 | sean-k-mooney | althogh i dont know if we want to just swap or add new tests | |
| 14:41:17 | bauzas | I just wanna make sure what we will do | |
| 14:41:37 | sean-k-mooney | largly for placment it wont matter much | |
| 14:41:39 | dansmith | oh sorry I thought you meant you thought we weren't getting any old coverage | |
| 14:41:48 | sean-k-mooney | as we always talk to it as admin more or less now anyway | |
| 14:41:49 | dansmith | right doesn't matter much for placement | |
| 14:42:56 | dansmith | glance does have a functional job running on both, but mostly because they have specific functional tests for it and their functional tests are a lot more realistic than ours | |
| 14:43:14 | dansmith | do we even do policy checking in our functionals? maybe some of them? | |
| 14:45:26 | bauzas | we don't check policy in our tests AFAIK | |
| 14:45:29 | bauzas | butn, | |
| 14:45:59 | bauzas | we sometimes ask for the admin role | |
| 14:46:39 | bauzas | so I guess that while nova will work with new defaults, we'll then call placement using old defaults, right? | |
| 14:47:49 | opendevreview | Sofia Enriquez proposed openstack/nova master: WIP: Implement encryption on backingStore https://review.opendev.org/c/openstack/nova/+/870012 | |
| 14:48:52 | dansmith | bauzas: I don't know that there's really much difference for placement | |
| 14:49:05 | dansmith | admin is still admin, and we don't use the user's token like we do when we call neutron, cinder, etc | |
| 14:56:17 | dansmith | I've also seen this grenade failure where we fail on the old side waiting for compute to be registered in the catalog | |
| 15:12:48 | dansmith | bauzas: gibi sean-k-mooney: it would be really good to get this in as soon as we can, it's seriously annoying debugging the other gate fails without it: https://review.opendev.org/c/openstack/nova/+/869900 | |
| 15:14:22 | bauzas | dansmith: gmann: sent new RBAC defaults patch to the gate | |
| 15:14:29 | bauzas | looking now at your CI fix | |
| 15:14:33 | dansmith | bauzas: thanks | |
| 15:16:19 | dansmith | bauzas: that 9900 patch avoids us spewing thousands of warnings on each run about that deprecated function, | |
| 15:16:27 | dansmith | which makes reading other log dumps pretty hard | |
| 15:17:23 | bauzas | dansmith: I don't see what you mean :p https://review.opendev.org/c/openstack/oslo.messaging/+/862419/4/oslo_messaging/rpc/client.py#389 | |
| 15:17:29 | bauzas | (joking) | |
| 15:17:41 | dansmith | mmhmm :) | |
| 15:17:42 | bauzas | every single instanciation raises a warning | |
| 15:17:47 | bauzas | lovely | |
| 15:17:57 | dansmith | yeah, which we apparently do A LOT | |
| 15:18:28 | bauzas | I wasn't expecting it | |
| 15:18:45 | bauzas | but I guess those are for tests | |
| 15:18:48 | dansmith | 15,664 times in just one n-api log run | |
| 15:18:54 | bauzas | https://review.opendev.org/c/openstack/nova/+/869900/6/nova/tests/fixtures/nova.py | |
| 15:19:00 | dansmith | search RPC in here: https://391a5777f99d615e9bdd-6109476be9a7a65d8252c7a651ade8fd.ssl.cf1.rackcdn.com/863919/6/check/tempest-integrated-compute/6af4a31/controller/logs/screen-n-api.txt | |
| 15:19:08 | bauzas | woah | |
| 15:19:08 | dansmith | we log it even in production, tens of thousands of times | |
| 15:19:24 | dansmith | and by "we" I mean "we on behalf of o.msg" | |
| 15:19:34 | sean-k-mooney | so any reason fro me to not +2w this | |
| 15:19:35 | bauzas | oh wait | |
| 15:19:38 | sean-k-mooney | it looks ok to me | |
| 15:19:42 | bauzas | this isn't a singleton | |
| 15:19:44 | sean-k-mooney | it has the requiremtn bump | |
| 15:20:02 | dansmith | https://imgur.com/a/0Vvw1ss | |
| 15:20:02 | sean-k-mooney | ci will kick it back if it fails again on the recheck | |
| 15:20:04 | bauzas | sean-k-mooney: sent to the gate too, for the gosh sake we could merge it eventually | |
| 15:20:22 | dansmith | note the scroll bar showing all the matches | |
| 15:20:28 | bauzas | dansmith: yeah, look at https://review.opendev.org/c/openstack/nova/+/869900/6/nova/rpc.py | |
| 15:20:38 | sean-k-mooney | what was the nova-next failure | |
| 15:20:39 | dansmith | yup | |
| 15:20:42 | bauzas | everytime we call get_client, we instantiate a RPCService | |
| 15:20:50 | dansmith | yup | |
| 15:21:22 | bauzas | I would have preferred this being a singleton, but meh noxw | |
| 15:21:23 | bauzas | now | |
| 15:21:28 | dansmith | well, | |
| 15:21:35 | gmann | dansmith: bauzas dansmith : for functional test testing placement new defaults. I will switch it once placement new defaults are merged, otherwise we need to add system scope token to make placement exiting defaults - https://review.opendev.org/c/openstack/placement/+/865618 | |
| 15:21:39 | dansmith | it can't always be because of cell stuff so we need to pool | |
| 15:21:51 | bauzas | dansmith: ah true | |
| 15:22:01 | bauzas | gmann: wfm | |
| 15:23:11 | gmann | dansmith: bauzas: sean-k-mooney: as you were on rbac things, can you check this which was missed in original change. keeping legacy admin for 'os-tenant-networks' policy https://review.opendev.org/c/openstack/nova/+/865071 | |
| 15:25:04 | sean-k-mooney | oh thats projec treader of gloabl admin | |
| 15:25:15 | sean-k-mooney | where as the curren tbehavior woudl requrie you to have admin on the current project | |
| 15:26:01 | gmann | yeah keeping legacy admin unimpacted | |
| 15:26:15 | sean-k-mooney | i.e. admin implies member implies reader but the project reader will also check the project in your token matches | |
| 15:27:09 | sean-k-mooney | i guess we dont have any tempest tests covering that | |
| 15:27:37 | sean-k-mooney | or it would have blocked eitehr enablign the new default or where we broke it | |
| 15:31:54 | gmann | sean-k-mooney: this ADMIN is just role:admin not just project admin. so rule is "role:admin or project-reader" where we do not check project_id for admin role token | |